Privacy Policy
Effective date: 30 July 2026 · Version v1.0-pilot
1. About this policy
This Privacy Policy explains how Digs collects, uses and shares personal data when you use our website, app, forms, communications or related online services. Digs is an online platform operating in beta; features may change as we develop the service. This policy applies to everyone who uses or interacts with Digs, including account holders, prospective users, property and business contacts, and people who communicate with us. Digs is for people aged 18 and over — please do not use Digs if you are under 18.
2. Who is responsible for your data
For the purposes of UK data protection law, AIVANCI LTD, trading as Digs, is the controller of the personal data described here, which means we decide how and why it is used. AIVANCI LTD is a company registered in England and Wales under company number 16823149, with registered office at Colony - Flint Glass Works, 64 Jersey Street, Manchester, England, M4 6JW. You can contact us about privacy matters at info@aivanci.com. AIVANCI LTD, trading as Digs, is arranging ICO registration before accepting pilot registrations involving personal data.
3. Personal data we collect
We collect the information needed to provide, manage, secure and improve Digs:
- Account and contact details — such as your name, email address, phone number (if provided), city or area, your institution or organisation (if provided), and basic account and authentication information.
- Service information you provide — your housing requirements, preferences and criteria, budget and timing information where relevant, request details, status, and any notes or free text you choose to add.
- Request, activity and consent records — the requests and enquiries you submit, your consent choices, records of when and how consent was given or withdrawn, service communications, and activity connected to your use of the platform.
- Optional profile information — if you use optional profile or housemate-introduction features, a short bio, photos or other media, household or lifestyle preferences, and, only if you choose to provide it and give separate explicit consent, your gender and any housemate gender preference. These features are optional; you can stop using them or ask us to remove this information.
- Safety and moderation information — reports, blocks, misuse concerns, moderation decisions, account restrictions and related communications.
- Property and business contacts — if you interact with Digs in a business or property capacity, your name, company or trading name, email, phone, city or area, and information you provide in connection with the service.
- Technical and usage information — authentication and session data, device, browser and usage information, security logs, and low-identifiability analytics data. Our analytics are configured so that they do not intentionally include names, emails, phone numbers, photos, free-text notes, message content, precise addresses, gender identity or trans-status signals, or other directly identifying or sensitive user-submitted content.
4. Information we do not ask for
Digs does not ask you to provide most special-category or highly sensitive personal data and does not need it to provide the core service. Please do not submit sensitive or protected-characteristic information, including details about race or ethnicity, religion or beliefs, sexuality, disability, physical or mental health, political opinions, trade union membership, genetic or biometric data, criminal records, nationality or immigration status, or identity, visa or financial documents.
If you include this type of information despite this warning, we may delete, redact, restrict or securely handle it where necessary to operate the service, protect users, comply with law, handle complaints, or establish, exercise or defend legal claims. Preferences and practical information you submit must not be used for unlawful discrimination.
Optional gender for housemate matching. Separately, if gender matching is ever enabled, you may choose to tell us your gender to help us suggest compatible housemates. Gender-related answers are optional, can be skipped, require separate explicit consent, are never shown to landlords or agents, and are never used to match you to properties. Gender matching and LGBTQ+ household signals are OFF for the pilot unless separately approved. We treat gender self-describe, non-binary and similar information as potentially special-category data where it could reveal gender identity or trans status, and we apply explicit-consent, access-control, no-hard-exclusion and no-analytics safeguards. You can withdraw consent at any time, after which we stop using the gender signal and remove it from active matching fields where technically feasible while keeping necessary consent/audit records.
5. How we use personal data
We use personal data to create and manage accounts; provide and operate Digs; understand and process your requests; identify relevant options within the service; manage communications and optional features; record consent choices; keep the service safe; moderate content and handle reports; prevent misuse; send service messages; improve the product; maintain service records; comply with legal obligations; and handle complaints, disputes and privacy-rights requests. We do not sell your personal data.
6. Matching and recommendations
We may use your profile and preferences to identify relevant housing options for you before any of your contact details are shared with a landlord or agent. Your identifying details are shared externally only when you give consent for a specific enquiry (see section 8).
If you use our optional housemate-introduction features and choose to provide a gender and a housemate gender preference, we may use them, with your separate explicit consent, only as a soft housemate-compatibility signal within those features. We do not use gender as a hard exclusion filter, do not use it to match you to properties, do not include it in match reasons or analytics, and never share it with landlords or agents. You can withdraw this consent at any time, after which we stop using your gender for matching and remove it from active matching fields where technically feasible.
7. Our lawful bases
We use personal data only where we have a lawful basis under UK data protection law. In summary:
- Creating and managing your account — contract, or steps before entering a contract.
- Providing, operating, securing and improving Digs, processing your requests, identifying relevant options, preventing misuse, and content moderation and reports — contract and/or legitimate interests.
- Sharing your contact details with an external contact for a specific request, optional profile/introduction features, and marketing emails — consent (unless another lawful basis clearly applies to a specific case).
- Legal compliance — legal obligation.
- Complaints, disputes and legal claims — legitimate interests or legal obligation.
- Product analytics — legitimate interests, subject to cookie/storage consent where required.
Our legitimate interests include operating, securing and improving Digs, processing requests, preventing misuse, maintaining records, and supporting safe use of the platform. You can object to processing based on legitimate interests, or withdraw consent, at any time by contacting info@aivanci.com.
8. When we share personal data
Sharing for a specific request. Where a request requires us to share your contact details with an external contact (such as a landlord or agent), we do this only where you have consented to that specific request, or where another lawful basis clearly applies. You can withdraw consent at any time; withdrawal does not undo sharing that has already happened, but we will stop further sharing where we can.
Service providers. We use providers to help us operate, secure and improve Digs — including hosting, database and file storage, authentication, email delivery, analytics, AI-assisted support, and security and operational tools. They may process personal data for us only as needed to provide their services.
Authorised staff review. Authorised Digs staff may review profiles, photos, notes, matches, proposed introductions, consent records and moderation/safety information where needed to operate the service, support users, review matches, handle reports, prevent misuse and comply with legal obligations.
Legal, safety and professional purposes. We may share information with professional advisers, insurers, regulators, law enforcement, courts or other parties where necessary for legal, safety, regulatory or dispute-related purposes.
Business changes. If Digs is sold, merged, reorganised or transferred, personal data may be transferred as part of that process, subject to appropriate protections.
9. AI-assisted support
Digs may use AI-assisted tools to help organise information, support service operations and prepare draft content or summaries. AI-assisted output may be incomplete or inaccurate. We do not make decisions about users that produce legal or similarly significant effects based solely on automated processing. Where AI processing of personal data requires extra consent or processor review, those features stay off or use a deterministic non-AI fallback until cleared.
10. Cookies and similar technologies
We use technologies that are strictly necessary for authentication, security and operating the service. We may also use analytics technologies to understand how Digs is used and improve it. Where cookies, local storage or similar technologies are not strictly necessary, we use them only where we have the required consent or where they are configured so that consent is not required.
11. Marketing
We may send service messages about your account, requests, security, consent choices and important updates. We will only send marketing emails where we have a valid lawful basis; our intended approach for the beta is a separate marketing opt-in. You can unsubscribe from marketing at any time.
12. International transfers
Some of our service providers may process personal data outside the UK. Where this happens, we use appropriate safeguards required by data protection law — such as adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to EU Standard Contractual Clauses, or other approved safeguards.
13. How long we keep personal data
We keep personal data only for as long as reasonably necessary for the purposes in this policy. For the pilot, we use the following retention schedule unless a legal, safety, dispute or audit reason requires a different period:
- Account, profile and intake data: kept while your account is active, then deleted or anonymised within 90 days of an account-closure or deletion request where technically feasible.
- Match/admin notes: kept during pilot operations, then reviewed and deleted or anonymised after 12 months unless needed for safety, dispute, legal or audit reasons.
- Photos/uploads: deleted when you remove them or your account is deleted; otherwise kept while your profile is active.
- Consent and legal acceptance records: kept for up to 6 years to evidence consent and terms/privacy acceptance history.
- Support and privacy-rights requests: kept for up to 6 years for audit, dispute handling and legal compliance.
- Raw operational/error logs containing personal data: kept for up to 180 days.
- Pseudonymous product analytics: kept for up to 24 months for product development, safety, reliability and funnel improvement.
- Aggregated or effectively anonymised analytics: kept indefinitely.
Analytics must exclude sensitive profile fields, free-text notes, gender identity/trans-status signals, photos, message contents, precise addresses and special-category data unless separately approved. If you delete your account, directly linked analytics identifiers should be deleted or irreversibly anonymised where technically feasible.
14. Security
We use technical and organisational measures designed to protect personal data, including encryption in transit, access and authentication controls, private storage where appropriate, limited internal access, security logging, supplier due diligence, and moderation and misuse controls. No online service is completely secure, but we work to reduce risk and respond appropriately to security issues.
15. Your rights
Under UK data protection law you may have the right to access your personal data; correct inaccurate data; ask us to delete it; restrict or object to certain uses; receive certain data in a portable format; and withdraw consent. To make a request, contact info@aivanci.com. We may need to verify your identity, and we normally respond within one month unless the law allows longer.
16. Complaints
If you have a privacy concern, please contact us at info@aivanci.com. You can also complain to the Information Commissioner's Office (ICO), the UK data protection regulator.
17. Changes to this policy
We may update this Privacy Policy from time to time. If we make material changes, we will take reasonable steps to let users know. The latest version will always be available at /privacy.
See also our Terms of Service.